Canonical, Ubuntu, and Why I Seem so Upset About Them All the Time
mjg59.dreamwidth.org
mjg59.dreamwidth.org
We FOSS devs rightly care less about market share because market share is not, and never has been, what sustains the FOSS ecosystem. What sustains it is the code content that attracts developers from all over the globe to look at it, learn from it, be interested and inspired by it, and the principles of freedom enables them to contribute to it and sustain this cycle.
(edit: downvotes are not for comments you disagree with. That's what responses are for. Stop abusing the system selfishly.)
I didn't downvote your post, but your statement about downvoting isn't true. It's certainly not in the guidelines[0]. And if one needs an appeal to the HN operators, as others have pointed out on separate occasions where your claim has been made, pg has previously said downvoting for disagreement is fine[1]:
I think it's ok to use the up and down arrows to express agreement. Obviously the uparrows aren't only for applauding politeness, so it seems reasonable that the downarrows aren't only for booing rudeness.
One litmus test for unhelpful commenting is, that the word 'you' is used. I try to keep it on topic, and the topic is never the other commenters.
It discourages open discussion.
I have never felt the need to down-vote. I hope I never turn into that guy.
I inderstand moderation. I understand the up-vote. Why make a post unreadable? If needed--put a minus sign on the post, but don't make it difficult for people to read. These posts go onto Google forever. It's just un-American. That's been my only gripe with this site.
And hardly anyone cares about pg's opinion, especially in a thread about FOSS, to which he has contributed fairly little.
I use software from free software ecosystem for the no bullshit, high quality software that it delivers. People like me would benefit from free software being more mainstream.
It isn't obvious that you benefit from this, there certainly is a kind of "eternal september" effect which makes popular software worse.
For example, in the good old days googling for Linux driver related issues yielded useful posts explaining what's going on and how to make things work, but when Ubuntu gained popularity the results suddenly became flooded with posts by clueless Ubuntu noobs trying package up/downgrades, alternative repositories etc without any understanding what they are doing and why.
I think it's getting better now, mainly thanks to sites like stackoverflow, but few years there was no way to get usable results without "-ubuntu".
Here's a direct response.
Telling someone they don't 'understand' something is abrasive and mean-spirited. Your paragraph on FOSS is your opinion, you don't represent FOSS or "the community". Not everyone thinks the same as you, and people are entitled to have different opinions. Personally, I care lots about FOSS being widely used, think market share does sustain the FOSS ecosytem (who pays developers?) and I'm damm sure I understand FOSS just fine thank you: again that's just my personal opinion and I don't go round giving it some higher moral equivalence to other peoples.
As a FOSS developer what's not opinion is the license you use on your code. The license is real, the rest is heat and noise. By definition, people will take your code and use it (that was the point right), and sometimes that's going to mean they'll use it in ways you disagree with. Your entitled to have an opinion on how someone is using the license (as is anyone, all equally), but you either have to convince them to agree with you or take them to court.
It is no more abrasive, than to dismiss someone's concerns as "protecting a sacred cow". I don't think either was abrasive, worthy of a downvote at any rate. I did not downvote the OP, I only wrote to disagree.
> I'm damm sure I understand FOSS just fine thank you
Great, then write some more specific things about why I'm wrong instead of complaining that I'm not polite enough, without actually applying the same standards to the comments coming from the same viewpoint that you happen to agree with.
> market share does sustain the FOSS ecosytem
Sometimes market share does sustain the FOSS ecosystem indirectly. Many other ways of increasing market share do not sustain it at all. So growing a large user base for its own sake should not be one's primary goal or strategy. I'm quite happy to elaborate more but it's probably more suitable for an essay.
Since that comment is aimed at me I should probably chime in now and say that my comment about "sacred cows" has been misinterpreted. I was stating that I don't have any hidden agendas, I was not trying to imply that the author of the original article had any "sacred cows". In other words, I was emphasizing the fact that I am a reasonably independent outsider.
a. "[I] care less about market share because market share is not, and never has been, what sustains the FOSS ecosystem"
b. "Sometimes market share does sustain the FOSS ecosystem indirectly"
I disagreed with what you said the first time. The second response is different because you're accepting that sometimes market share does sustain FOSS. You're also saying that sometimes building market share does not improve the sustainability of FOSS: I can accept that as true easily.
If you accept that sometimes it does sustain FOSS, then the questions are what level of "sustaining" you want and what you precisely mean by the FOSS ecosystem
My definition of sustain would be quite simple, I want to see FOSS developing quickly and end-users receiving the benefit of using free software. Notice my definition of "FOSS ecosystem" includes users, and the variety of contributions from supporting FOSS, to working on documentation through to development.
Consequently, market share is important to me because more users means more contributors: both paid and unpaid. Without paid developers there would be no Intel graphics/networking for Linux, no Python, no Firefox or any of RedHat or Ubuntu. The larger your market share the more paid developers you can attract which speeds innovation overall. That is not to negate the work of unpaid developers who have done and do fantastic work in FOSS: if there were no commercial developers there would still be FOSS but it wouldn't be as developed or as mature. The capabilities and speed of innovation within FOSS without full time paid developers would be fundamentally different.
Your last point is that as "sometimes" market-share does not sustain the FOSS ecosystem then it should not be the "primary" goal "for it's own sake". You'd have to write a longer essay as I don't see how that point follows. I'm sure some market share increase for FOSS doesn't increase the number of contributors. But overall I perceive a positive spinning wheel where more market share (e.g users) means more contributors to FOSS both paid and unpaid. In fact, I think we already have fantastic FOSS, if there were 'units of effort' to spend on improving the FOSS ecosystem I would be all-in spending them all on increasing the number of users.
There are many different ways to achieve market share, and these different strategies have (a) many consequences beyond merely (b) getting more paid developers. Even though (b) can help the FOSS ecosystem, in many cases (a) includes effects that harm the FOSS ecosystem, that more than offsets (b). For example, this mjg59 article talks about Canonical's trademarks. This can be argued to "increase market share" but it undermines the principles of FOSS, and prevents other developers from building on top of much of Ubuntu et al. (edit: another thing is not bothering to spend money on core infrastructure products because they're less attractive to users; OpenSSL is one famous example but there are much better pieces of software out there that deserve similar if not more levels of funding.)
Another thing to consider long-term and short-term effects. Even if one big company really does FOSS genuinely well for a short time, if they capture 99% market share that is still an uncomfortable situation, because eventually there is a massive risk they will ditch the FOSS part and turn parts of their software ecosystem less free (now that everyone is locked in). The risk increases with churn as new executives are brought in, that don't care about the values of the previous executives. (edit: the risk is less with a product that is more easy to fork, e.g. software that does not used centralised services, and FOSS already carries this quality somewhat.)
Mine are to avoid enacting barriers to having my code used on systems where failures mean people could die. The GPL is not an ideal license for that, but there are worse licenses. One example of why the GPL is not an ideal license for that is that US federal law prohibits the GPLv3 in automobiles because it mandates tivoization. If choices are between good code under the GPLv3 and bad code under a license the law permits, the bad code is used and then we get things like Toyota vehicles' drive by wire being able to live up to the saying, "Always moving forward". In this example, this also affects people outside the US whenever the engineering is reused and I doubt any automaker would design 1 drive by wire for the US and another for everyone else using GPL code that is well known to be superior to their embedded garbage. This is far from the only example and not all examples involve federal law. However, if you write something good that could have a mission critical application, it is good enough that the alternative code is more likely to kill people and your principles are to exclude anyone who does not do exactly what you want them to do with it, you can have your principles, but people might die as a result. If deaths occur and those dying from it include the principled person who could have saved them, having those principles would be what killed that person. Having the developer die too in such situations is improbable, but it is something I consider when I ask myself "what do I want a software license to do?".
It seems like your counterexample simply highlights yet another discontinuity in US law.
The entire point of free software is to allow it to be endlessly copied, modified, and distributed. This is why we have things like Android and WebKit and the firmware on your home router. They're all based on free software. It may not be "good branding" for there to be hundreds of Linux distros, but that's not what any of this is about.
The main Desktop distros are all fairly equal now. Ubuntu, Mint, OpenSUSE (My favorite), and Fedora are all fairly straight forward and ready to be used and abused.
Arch Linux goes out of their way to just make it hard but that has even stopped, heck their community has changed drastically over the past five years. I still use it on my ancient machines (32 bit is dying though).
I want to install just about anything I can do OpenSUSE's one click or the SUSE build service, go through the pain of PPA or Fedora's flavor of the year installer of outside packages. In Arch you have AUR. It is vastly different then the way it was just 8 years ago or the way Slackware currently is made.
Heck even the RPM vs DEB stupidity is mostly over. I think it has been over a year since someone said I don't do RPM based systems due to dependency hell which was just a issue from 10 years ago that got fixed but that stupid line kept getting repeated all the time!!!! I always told them build a DEB and an RPM and you will see why this is an non-issue.
Given that there are about 7+ billion people on earth, I have a very difficult time trying to understand what “linux fragmentation” is. If you think we should all use the same OS, does the same thought process applies to governments, shoes, food, etc?
Btw, people from almost any domain represent small minority compared to seven billion people.
Not sure where are you going with that. There are several hundred different models of car for sale around the world. And still several hundred that count.
There are some tens of Linux distros that count. That is indeed evidence that people mostly don't care about them, and that's what the GP was arguing.
In 2004, the entire Ubuntu distribution team fit into a small conference room and still managed to produce a new distribution that was significantly more compelling than any other available at the time. They were able to do this because Debian provided a convenient base and was released under a license that made this possible. If Canonical had been forced to modify every package in order to remove every reference to Debian, there would be no Ubuntu.
The same might happen again. There's no reason to believe that Ubuntu is the final stage in the evolution of desktop Linux, but right now it's probably the most credible. If someone wants to be able to experiment then they should be able to do so. We don't produce better software by stifling creativity for no reason other than brand protection.
frankly i think Canonical is trying to avoid a "Oracle Linux" scenario happening to Ubuntu.
This makes no sense. Having patch sets or a single huge tarball is exactly the same as far as CentOS is concerned. Also, the patch sets for RHEL6 would be around four times the size of the kernel itself so there are also practical reasons to stop distributing them (of course Oracle _is_ a reason, I'm not denying that).
The delay in CentOS 6 was due to personal reasons, not to the change in the distribution policy for kernel patch sets.
CentOS was acqui-hired because Red Hat needed CentOS as the base for community development of its RHEL-based products (oVirt for RHEV, RDO for RH OpenStack, and so on).
So we find ourselves in a situation where the article author is apparently arguing against group X because they're trying to subvert the intention of the GPL, and using as evidence a definition provided by group Y, who tried to subvert the intention of the GPL.
You can make it, yes, but it's not a very convincing one.
https://www.youtube.com/watch?v=PaKIZ7gJlRU
> since they wrote both the GPL itself and the four freedoms
Also, having been part of organisations that have operated against their own philosophical principles and mission statements, I don't accept that the FSF is immune to changing their angle on things. And having hung around plenty of radical progressives growing up, I've seen some handy re-rationalisations of earlier positions.
Overall, I'm on the side of the FSF. But fucked if I'm going to be part of this thing that progressives do, which is piss all over their allies (in this case, ubuntu) just because their opinion is slightly different to one's own. If someone's going to raise the "nuh-uh, subversion of license = evil", then fuck it, here is a video of someone at the heart of the whole licensing debate literally saying that the FSF behaved immorally about licenses too.
But you have a second point: how you treat your allies and other sympathetic parties. Sadly, idealism seems to trend towards that behavior and it's pretty counterproductive.
Re: the idealism stuff, my armchair psychology take on it is this: conservatives are passionate about things not changing, so minor differences don't matter so much because the overall goal is the same; progressives are passionate about things changing, so if the cart is going to move at all, it really needs to go in my direction. Add in the human predeliction for not seeing the forest for the trees, and the progressives will squabble over what really are minor differences.
There are reasonable argument pro and con the whole "Gnu Linux" thing, many of them silly and some cogent. But nobody was subverting (or attempting to) anything that I can see.
Seemed like it was to undermine Linus and place GNU on the same level as Linux kernel. (hurd) Don't get me wrong RMS is someone I am glad is alive and engaged with the community but I disagree with him most of the time.
Seemed like it was to undermine Linus and place GNU on the same level as Linux kernel.
I don't agree with your characterization at all, but let's not go over old ground.> Canonical's uncooperative and unclear stance towards the community
Uncooperative and unclear? The 'flat refusal' linked in the main article is pretty clear and cooperative. "Do this thing at this link and we'll be cool with it, and we have a track record of being so". Sounds clear and cooperative to me.
> whose contributions enable it to exist
This is the kind of shit I mean above when I say pissing on allies. You're painting ubuntu as a parasite rather than an ally. Ubuntu has done plenty to help the community and is part of that community - in particular, they took making a non-techie friendly desktop and driving that goal forward as their specialty. Do they do everything perfectly? No, but none of the major players do.
I mix debian and ubuntu in my work, and the debian/FSF purists really puzzle me sometimes. One friend of mine read mjg's comments on the same issue on lwn and bought it hook, line and sinker. Started arguing with me that there was zero difference between Apple and Canonical, simply because although Canonical provide you with their source code, you need a little more elbow-grease to make a derivative of their whole integrated environment (which is a violation of a very liberally-read 'freedom 2', apparently). You're free to make that derivative, but it's just not as simple as removing one package. Apparently this makes them the same as a corporation famous for it's industrial secrecy and lockdown of user capabilities, and who has had the police raid someone's home because they thought one of their prototypes was there. It's a ridiculously binary view of the world.
(There are probably also situations where that would be a terrible line of reasoning.)
In a way, it mirrors the difference between free markets and command economies. Free markets tend to be resilient, offer individuals the most power, and tend to favor those with skill at the expense of lots of market fragmentation and inefficiency. Command economies, by contrast, can have everything working together towards one common goal, and allow for every individual to have some measure of equality and security. They can operate with either far more efficiency than a free market, or far less... and the fortunes can rapidly change.
Democracies respond by then copying the innovation of the risky dictatorial/command experiments.
Ubuntu is trying to do a little of both. It tries to be like Apple, and thus doesn't try to conform to the general FOSS community initiatives if it thinks they aren't innovating correctly or quickly enough. That is why they created Unity, Mir, and many other in-house projects. Tightly integrating branding into the products is just par for the course.
By not trying to go along with the program, they annoy everyone else. But since the Debian Technical Committee, X Foundation, Linux Foundation, and W3C committees are not like the Comintern or the Apple board of directors, they have no power to enforce that program. Hence the fragmentation.
We need to define what it means to be efficient: I use efficiency to mean the measure of how market producers meet the demands of market consumers. In these cases a central planning authority cannot obtain enough actionable data from the market nor can it act on it in a timely enough way as to actually meet that definition of efficiency. Individual consumers have differing wants and needs: differing to the point that you would be hard pressed to define the difference between what constitutes a want vs a need in all cases. Even the best central planners would be hard pressed to deal with such complexity. You may be able to use prior consumption numbers to plan the next cycle, but things change. Also adoption of new technology (not just computer technology) is difficult to understand. When the car is invented does the command economy order a bunch to see how it plays out? Does it order none because there were no prior demands expressed? Can it even be invented or manufactured because the likelihood of seeing it even get considered so small as to make it not worth it... or needed enabling technologies like, say, better lathes (or some such thing) not developed for a car that may exist because there is no purpose for it now, or because there is no reward for pursuing such a path to the inventor? How does one set prices or does one dictate consumption as well? Fail in pricing and you have shortages for one thing and over-abundances for another. This goes on and on. And again, these are the questions outside graft and ill-will from the central authorities.
Free markets on the other hand distribute the penalties and rewards based purely on how well a producer meets a consumers requirements (note that this is different from producing a perfect world for the consumer... consumers have a limit of what is acceptable, so you may buy something you wish was much better/cheaper/etc than it was, but you still concluded that you'd be worse off having the money rather than the product so you traded... a need was met). An individual producer can focus on a an individual area of need for specific consumers much better than a central authority can; and if the existing producers fail some consumers, an opportunity for other producers to enter the marketplace exists. If a producer meets consumer demand in a way that maximizes the resources that production itself consumes, they have the resources to continue to serve the market; if they fail to meet consumer demand in a resource efficient manner, they cease to be in the market.
Profit is the measure of efficiency of meeting a consumer demand: you have bad profits, you're not efficient in some way, good profits and you are. Rewards and "punishments" from the market itself coordinate resources and do so quickly and without needing to wait for the next 5 year plan. In command economies, if consumer needs aren't met, rarely are there any bad outcomes for the producers (the state). You can't choose to buy from the other guy because there is no other guy. And to reward good outcomes? Why bother when you control the rewards and the penalties either way?
Anyway, to bring it all home, fragmentation in the Linux world is really about this random walk of producers trying to meet needs: the interesting question is, "who's needs"? Ubuntu is shooting for customers: those not interested in building the operating systems/tools and those that just want to use it. Red Hat is similar except for a narrower set of consumers. But, say, Debian (to some degree), or even better Slackware (a personal old favorite)... who is the consumer? I would argue that often times it is the developer/maintainer that is actually the consumer: they consume their leisure time and make other consumer expenses because of their desire to engage in the activity of developing or maintaining a distribution; OK, maybe less so Debian than Slackware, but I think the point still applies. Many of these distributions don't exist because an entrepreneur was trying to reach an underserved market... they exist because the developer/maintainer set out to achieve personal goals. As such a distribution cannot fail on adoption rates or by using monetary success measures since the reward/punishment is really a matter of developer satisfaction in the pursuit. That's also not to say that these personal pursuits cannot also be commercial pursuits or that developers don't want to see their work adopted by others, but the primary motivation will not weed out less successful distributions because they are actually successful for what the makers tried to accomplish. And in that sense, they are meeting a need and that is actually efficient... just not in the way you may desire or expect.
Planning occurs in markets too. A Boeing jet takes decades to bring it to market, and the organization must make risky long term plans and bets. They may pan out, or may not. But every entrepreneur and startup at YC is doing the same sort of thing. Taking losses for years, even, because of a belief in their plan.
Sometimes, risky bets pay out. Sometimes spectacularly. And sometimes they crash and burn. The resilience of a market economy means that not everyone has to be on board for such a venture. Indeed, the market is a collection of organizations that are all either slowly or quickly in the process of failing. None of them will last forever, but they generally won't all fail at the same time. A command economy can, and often does.
Other types of economic planning that we see have included nuclear energy, damns, highways, railways, satellites, and so on.
The US only began funding space exploration after they realized that the USSR was ahead. The US was able to be more resilient over time, and still incorporate a lot of the top-down innovations.
The average Joe does not care much about the open source philosophy. If it's free and works well out of the box without having to touch the command line, they would be happy. This is where I think Linux mint wins even though it includes many proprietary codecs.
It looks and works like Windows 7 and most people would feel comfortable using it.
For old computer hardware choose the lightweight Mate edition of Linux mint.
Ubuntu had its break through when it was the first one to get things to be more standard. Now with Systemd and easy build systems https://build.opensuse.org/ just about anyone can get a basic computer going quickly and easily. I still think Windows is the hardest and longest OS to install.
But they have gotten way better, too. The last Windows that I regularly used was XP, and I remember it being a pain in the ass to set up (on the scale of "I'll dedicate the whole weekend to getting the OS and drivers installed").
Just recently, though, I set up a dual-boot on my desktop PC, with Arch Linux as default, and Windows 10 for the few games in my Steam library that are not Linux-compatible. I explicitly chose Windows 10 for enabling my DirectX-12-compatible card.
The setup process was surprisingly straightforward and despite the very new hardware, it found all drivers out of the box and everything went smoothly. The only annoyance is the gazillion spying features that you have to disable, and the other gazillion spying features that you cannot disable. But since I'm only playing games on that OS, and the other OS with all personal data is on an encrypted disk, I don't care anyway.
A reasonable response: http://www.zdnet.com/article/no-microsoft-is-not-spying-on-y...
One day, one new group will be more focussed on graphics and hire UX designers, and publish a polished, paid version of Linux. As in, you can redistribute, but if you want to subscribe to the repository which contains the latest bugfixes and the awesome UI design upgrades, you'll have to pay - and this is perfectly legal with free software, even GPL. We've only avoided that until now because so many groups have a huge disdain to making money off products (which is an awesome value - but just a value).
So it is understandable that Ubuntu tries to raise barriers of entry.
That's not really true, GPL says nothing about standards, you can create your own proprietary standard with your code covered under GPL. Funnily enough you can have GPL software and create a minefield of confusion like Oracle does with the OpenJDK which is GPL.
I fully agree on the first point though. Sadly many people forget that.
If you're a Linux company, you don't have to restrict access to your code to make money, you can make money by offering something the community does not: support contracts. That's how Ubuntu makes its money now anyway (as far as I know), opening up access to the code will not affect that.
That reminds me of what elementary did, with their forced payments.
Recently I tried a bunch of Linux flavours, and it still pissed me off. No other distro forced me to do that.
Elementary claim making software takes effort, but how much are they contributing upstream - to Debian or to the kernel creators?
In the end, I ended up with Mint, which has a better UX anyway imo.
We are closing in on the definition of privilege here, aren't we? Being annoyed because you have to explicitly had to write (ok, update) a form to inform that you didn't want to pay?
download.com, yes, it is.
Then again, elementary OS is completely different as not only do they package a complete distro but they also create and maintain multiple programs.
Worse, users might even think their money goes towards "linux" – not that the money just ends up with devs who barely managed to write a desktop shell?
Aside from the fact that it is a very nice shell, what is this attitude (in a startup forum) that you shouldn't earn money?
Imagine I’d take Google’s Android Apps, add a new icon and a new theme to them "DARK THEME GMAIL", for example, and then tell everyone what a great app I made and sell it for 5$.
Most of what elementary is is a nice Linux distro – but just a distro, not even special support.
You pay for a product, where most of it was not actually made by the people you pay.
Is that fair? Is that even moral? No.
It’s still not morally okay to claim the work of someone else for yourself.
Wrong example. More like: If you don't want people to take and make a thousand copies of what you placed outside your garage and do whatever they want with it, don't place a sign outside your garage door that people are allowed to help themselves.
Yes, by all means do give back to the original author. Give credit, buy support agreements, recommend, report bugs etc etc. I'm happy to pay a little more than necessary here and there to support good projects (including elementary OS) and I push for a support agreement with the team that provide the wonderful server stack we use.
But don't tell me I have a moral obligation to not do something the license goes out of its way to allow me to do, please.
Oh, btw, people picking on elementary OS might have picked the wrong target : it is actually beautiful and works surprisingly well for some of us and it seems the money they get in goes towards bug bounties.
Bundling existing software with only minimal own involvement, and either scamming users with malware or by convincing them to pay?
Both Sourceforge and Elementary only produce a tiny amount of the code they sell (be it either a simple shell for a whole OS, or an install wizard for a most complex software).
Sourceforge 1m ago : yes
Reason : sourceforge tried to deliver something other than the users wanted, either by providing two misleading advertising on the download page or even by bundling adware/malware.
elementary provides something some people want and in exchange asks for money. This is something HN actively recommend again and again.
elementary just happens to be nice on a number of levels from letting you decide the price yourself to feeding the money back into development.
I'll make a webpage where I'll sell elementary.io then.
Obviously, the money stays completely on my account, but don't worry, the OS comes with a few additional programs I wrote (or, rather, will have written), like a nicer IRC client.
I have my doubts about whether this will make you rich but as long as you are being honest and honor the GPL etc I see no legal or moral problems.
BTW: I know that I personally was not scammed and I would guess nobody else who paid for it felt scammed either.
I think many like me are happy to chip in with a little money as I don't have capacity to contribute code or support.
Additionally, Ubuntu does the exact same thing, and has been doing it for longer than Elementary. As soon as you click "download" on their overview page, you're sent to a contribute page. Sure, Ubuntu has a link in plain text that directly says you can download without contributing, but it's not immediately apparent either.
Arguing that it's immoral for Elementary to ask for money, even if they don't fund Ubuntu, Debian, and the Linux Kernel directly is the same as arguing it's immoral for Canonical to ask for money because they either don't, or only very minimally fund Debian and the Linux Kernel from what I've seen.
It's not understandable if they violate the GPL in the process (the point of the article).
A short license does not mean that it will have fewer problems. It just means it addresses fewer concerns.
At any rate, the mjg is not complaining about software licenses, but about trademark policies. Trademarks are a very different set of laws than the copyrights that software licenses typically handle.
If you are building a new Linux distribution based on Ubuntu, I don't even understand why you would want to reuse binaries they built.
This post would be more meaningful if it literally quoted from unfavorable license terms used by Ubuntu to actually prevent people from making derivatives. Saying that Canonical "appears to require" something is using weasel words.
You'd think, but no - there's no guarantee that the shipped binary packages can be built with the shipped toolchain or shipped dependencies.
> If you are building a new Linux distribution based on Ubuntu, I don't even understand why you would want to reuse binaries they built.
Because it's entirely unnecessary? Building the entire archive is a huge amount of effort.
> This post would be more meaningful if it literally quoted from unfavorable license terms used by Ubuntu to actually prevent people from making derivatives. Saying that Canonical "appears to require" something is using weasel words.
The terms are at http://www.ubuntu.com/legal/terms-and-policies/intellectual-... - I probably should have linked them, I've just been writing about this enough lately that it's easy to forget that people might read a single post without context.
That problem will be with us as long as we use binaries as the primary means of distribution. If you consider that to be a problem, you could put effort into distributions where the packaging is the source code. I know I do.
> Because it's entirely unnecessary? Building the entire archive is a huge amount of effort.
How do you know that the source code provided actually corresponds to the binaries unless you compile them yourself[ with a toolchain you compiled yourself [...]]?
> The terms are at http://www.ubuntu.com/legal/terms-and-policies/intellectual-.... - I probably should have linked them, I've just been writing about this enough lately that it's easy to forget that people might read a single post without context.
No company's policies are perfect. You might be more effective trying to deal with the overall distribution of how software is done rather than imperfections in community leaders. There is a point of diminishing returns in focusing on a small subset of the companies out there while completely ignoring the rest.
I am typing this on a system running Gentoo that has only 3 proprietary packages installed, with one being Intel's microcode. In time, I hope to lower that number to zero. If you are concerned about this and do not run a source-based distribution, I suggest that you switch.
Anyway, I am happy to see that building from source is becoming easier for users of Debian and presumably Ubuntu by extension.
I do consider it to be a problem, but since reality is problematic I think policies that force people to rebuild all binaries before they can redistribute them are harmful.
> How do you know that the source code provided actually corresponds to the binaries unless you compile them yourself[ with a toolchain you compiled yourself [...]]?
I don't, but I also don't have a verifiable path to bootstrapping a toolchain. I trust that Canonical haven't backdoored their packages.
> You might be more effective trying to deal with the overall distribution of how software is done rather than imperfections in community leaders.
I'm interested in it being straightforward for people to produce modified derivatives of the market leader, ie Ubuntu. I can achieve that in two ways:
1) Helping convince Canonical to change their IP policy 2) Helping convince Canonical to rearchitect their entire distribution infrastructure
(1) strikes me as being easier, so that's what I've chosen to work on.
You do not need a verifiable path to bootstrapping a toolchain to reduce surface area of attack to just the toolchain.
That being said, you could try building Clang with GCC and then GCC with Clang (or vice versa) to break any exploits designed to persist in either one indefinitely unless you are the victim of a really special hypothetical attack that targets both simultaneously, although I imagine you could interleave multiple GCC and Clang versions to make such an attack even harder to pull off or even add more compilers to the mix like EKOPath. That should reduce the attack surface area to binutils.
You don't have a moral right to base a distribution on binaries produced by some other distribution. Unless you are going to produce actual evidence of a legal violation you really don't have anything here.
If the shipped source doesn't contain enough information to actually perform a build surely that's a straight-up GPL violation (and a far more serious one than any possible ZFS issue, and one that you're in a position to do something about as a copyright holder). If the shipped source doesn't include whatever their developers actually use to build (and I refuse to believe an organization like Ubuntu wouldn't have a unified "build it all" script, or at least a README that described the steps you needed to take) then how can it possibly be the preferred form for making modifications?
Why would it be? Build and testing systems for something like a Linux distribution are far more complex systems than a simple script. In any case, there's no requirement in the GPL (or any other OSI-approved license AFAIK) to include components outside of the software itself to simplify building and installing. Of course, there are a variety of things like package managers that do simplify the process but there's no requirement in the GPL that it be straightforward to install from sources.
Package A's source code contains some undefined behaviour that gcc 4.4 tolerates. The distribution upgrades to gcc 5.1 and the build now breaks, but nobody notices because no new version of Package A has been uploaded and so no new build has been performed. Is your position that it was in compliance with the GPL before the gcc transition, and in violation afterwards?
They don't.
I mean a developer working at Canonical, trying to make a change to one of the packages they're preparing for distribution, has to have some way to answer the question "what version of gcc is being used to build this package". Whether that information is kept in the source tree, on their wiki, or on a post-it on the employee fridge - in any case, it's part of the source in the preferred form for making modifications, because it's, well, part of what the employees use to make modifications.
I think that Matthew might be suggesting that not all packages are rebuilt with every release? A binary package might be compiled with GCC-4, then the distribution is upgraded to GCC-5, dropping GCC-4. If for some reason the package is not compatible with the new compiler, you would then be in a situation where the binary cannot be recreated from source without outside tools. Do you know if Canonical recompiles everything on each update to the toolchain?
The distribution isn't rebuilt every cycle. If no new source release has been uploaded, the existing binary will be used for the next release.